Adware

Adware.HiRu (file analysis)

Malware Removal

The Adware.HiRu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.HiRu virus can do?

  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Adware.HiRu?


File Info:

crc32: 460DD402
md5: 11e541e7bea806b43b8e7a40411c95e8
name: Ashampoo.WinOptimizer.v15.00.05.exe
sha1: 42a5e03e9a739d179ec371b15f1c346146d31e8b
sha256: 78c98b1a6675152fcd9ef672c65a9693372e0ec0bae2f3e4a9a7319d84683370
sha512: aa17f82c6ea3ffbaa840ad9ec32ac9d16b90dd40fb743a15990e099c2993fdf14d3737504e7d9f847dc644faa2116bc4b3f61ad4757d57e04e3f28e952a6ad9b
ssdeep: 196608:FKT+zrXjoQp4SYIfjhVBfVUIbgcEtGQY86lKyCdbuu3kQLKYnS1V1FLA:YT+zVvLh35bgc+vY86lsou3xGGiXK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Ashampoo Development GmbH & Co. KG
FileVersion: 15.00.05.0
CompanyName: Ashampoo Development GmbH & Co. KG
Comments:
ProductName: Ashampoo WinOptimizer v15.00.05
FileDescription: Ashampoo WinOptimizer v15.00.05
Translation: 0x0000 0x04b0

Adware.HiRu also known as:

MalwarebytesAdware.HiRu
K7GWTrojan ( 0053075f1 )
K7AntiVirusTrojan ( 0053075f1 )
SymantecPUA.Gen.2
TrendMicro-HouseCallTROJ_GEN.R002C0OF518
TrendMicroTROJ_GEN.R002C0OF518
CyrenW32/Trojan.IAQR-8842
WebrootW32.Trojan.GenKD
Endgamemalicious (moderate confidence)
ESET-NOD32NSIS/TrojanDropper.Addrop.B

How to remove Adware.HiRu?

Adware.HiRu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment